Microsoft Patches Three Actively Exploited Zero-Days
IPA warns that three Microsoft vulnerabilities are being actively exploited in the wild and urges immediate patching.
Japan's IPA issued an alert on July 14, 2021 regarding a Microsoft security update addressing multiple vulnerabilities. Among these, Microsoft confirmed active exploitation of CVE-2021-34448 (a scripting engine memory corruption vulnerability), CVE-2021-33771 (a Windows kernel elevation of privilege vulnerability), and CVE-2021-31979 (a Windows kernel elevation of privilege vulnerability). These flaws could allow attackers to crash applications or gain control of affected systems.
Given the confirmed in-the-wild exploitation, IPA urged users and organizations to apply Microsoft's patches immediately through Windows Update to prevent further damage. The advisory is largely informational, directing readers to Microsoft's official patch channels and the IPA Security Center for guidance, without providing additional technical details on the exploitation methods or threat actors involved.
Mentioned in this report
Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2021/20210714-ms.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free